2024 CVE Vulnerabilities
39,240 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-6373 | CRITICAL | 9.8 | 0.9% | Jun 27, 2024 | A vulnerability has been found in itsourcecode Online Food Ordering System up to 1.0 and classified as critical. This vu... |
| CVE-2024-6372 | CRITICAL | 9.8 | 0.6% | Jun 27, 2024 | A vulnerability, which was classified as critical, was found in itsourcecode Tailoring Management System 1.0. This affec... |
| CVE-2024-6371 | CRITICAL | 9.8 | 0.7% | Jun 27, 2024 | A vulnerability, which was classified as critical, has been found in itsourcecode Pool of Bethesda Online Reservation Sy... |
| CVE-2024-38515 | — | — | — | Jun 27, 2024 | Rejected reason: This CVE is a duplicate of CVE-2024-38374. |
| CVE-2024-1107 | CRITICAL | 9.8 | 0.5% | Jun 27, 2024 | Authorization Bypass Through User-Controlled Key vulnerability in Talya Informatics Travel APPS allows Exploiting Incorr... |
| CVE-2024-6370 | MEDIUM | 5.4 | 0.4% | Jun 27, 2024 | A vulnerability classified as problematic was found in LabVantage LIMS 2017. Affected by this vulnerability is an unknow... |
| CVE-2024-6369 | MEDIUM | 5.4 | 0.4% | Jun 27, 2024 | A vulnerability classified as problematic has been found in LabVantage LIMS 2017. Affected is an unknown function of the... |
| CVE-2024-6368 | MEDIUM | 5.4 | 0.4% | Jun 27, 2024 | A vulnerability was found in LabVantage LIMS 2017. It has been rated as problematic. This issue affects some unknown pro... |
| CVE-2024-6367 | MEDIUM | 5.4 | 0.4% | Jun 27, 2024 | A vulnerability was found in LabVantage LIMS 2017. It has been declared as problematic. This vulnerability affects unkno... |
| CVE-2024-6262 | MEDIUM | 6.4 | 0.3% | Jun 27, 2024 | The Portfolio Gallery – Image Gallery Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p... |
| CVE-2024-5535 | CRITICAL | 9.1 | 5.6% | Jun 27, 2024 | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an empty supported client protocols buffer ma... |
| CVE-2024-0949 | CRITICAL | 9.8 | 0.5% | Jun 27, 2024 | Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability... |
| CVE-2024-0947 | CRITICAL | 9.8 | 0.5% | Jun 27, 2024 | Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Sessi... |
| CVE-2024-4983 | MEDIUM | 5.4 | 0.4% | Jun 27, 2024 | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPre... |
| CVE-2024-5601 | MEDIUM | 5.4 | 0.3% | Jun 27, 2024 | The Create by Mediavine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Schema Meta s... |
| CVE-2024-22232 | HIGH | 7.7 | 0.8% | Jun 27, 2024 | A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user ca... |
| CVE-2024-22231 | MEDIUM | 5 | 0.7% | Jun 27, 2024 | Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can lead a malicious... |
| CVE-2024-4704 | MEDIUM | 6.1 | 0.4% | Jun 27, 2024 | The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and... |
| CVE-2024-4664 | MEDIUM | 4.8 | 0.4% | Jun 27, 2024 | The WP Chat App WordPress plugin before 3.6.5 does not sanitise and escape some of its settings, which could allow high ... |
| CVE-2024-3111 | MEDIUM | 5.4 | 0.3% | Jun 27, 2024 | The Interactive Content WordPress plugin before 1.15.8 does not validate uploads which could allow a Contributors and a... |
| CVE-2024-1330 | MEDIUM | 4.3 | 0.4% | Jun 27, 2024 | The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using som... |
| CVE-2024-6283 | MEDIUM | 5.4 | 0.3% | Jun 27, 2024 | The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of ... |
| CVE-2024-4570 | MEDIUM | 5.4 | 0.3% | Jun 27, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter i... |
| CVE-2024-4569 | MEDIUM | 5.4 | 0.4% | Jun 27, 2024 | The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter i... |
| CVE-2024-6054 | HIGH | 8.8 | 0.8% | Jun 27, 2024 | The Auto Featured Image plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now